1-1 · Cybersecurity Policies and Procedures 3
1-1-1
Cybersecurity Policies and Procedures — 1-1-1
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-1-2
Cybersecurity Policies and Procedures — 1-1-2
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-1-3
Cybersecurity Policies and Procedures — 1-1-3
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-2 · Cybersecurity Roles and Responsibilities 1
1-2-1
Cybersecurity Roles and Responsibilities — 1-2-1
Are OT/ICS cybersecurity roles and responsibilities defined and assigned (incl. governance and operations)?
RACI / roles matrix; appointment letters; org chart showing OT security ownership.
2 sub-controls
- 1-2-1-1 1-2-1-1
- 1-2-1-2 1-2-1-2
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-3 · Cybersecurity Risk Management 1
1-3-1
Cybersecurity Risk Management — 1-3-1
Is there an OT/ICS cybersecurity risk management methodology, with risk assessments performed and treated?
OT risk methodology; risk register/assessments; treatment plans & owners.
7 sub-controls
- 1-3-1-1 1-3-1-1
- 1-3-1-2 1-3-1-2
- 1-3-1-3 1-3-1-3
- 1-3-1-4 1-3-1-4
- 1-3-1-5 1-3-1-5
- 1-3-1-6 1-3-1-6
- 1-3-1-7 1-3-1-7
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
1-4 · Cybersecurity in Industrial Control System Project Management 2
1-4-1
Cybersecurity in Industrial Control System Project Management — 1-4-1
Are cybersecurity requirements embedded in OT/ICS project management (new systems, expansions, migrations)?
Project security requirements checklist; secure design/acceptance gates; sample project records.
4 sub-controls
- 1-4-1-1 1-4-1-1
- 1-4-1-2 1-4-1-2
- 1-4-1-3 1-4-1-3
- 1-4-1-4 1-4-1-4
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-4-2
Cybersecurity in Industrial Control System Project Management — 1-4-2
Are cybersecurity requirements embedded in OT/ICS project management (new systems, expansions, migrations)?
Project security requirements checklist; secure design/acceptance gates; sample project records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-5 · Cybersecurity in Change Management 4
1-5-1
Cybersecurity in Change Management — 1-5-1
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-2
Cybersecurity in Change Management — 1-5-2
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-3
Cybersecurity in Change Management — 1-5-3
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
5 sub-controls
- 1-5-3-1 1-5-3-1
- 1-5-3-2 1-5-3-2
- 1-5-3-3 1-5-3-3
- 1-5-3-4 1-5-3-4
- 1-5-3-5 1-5-3-5
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-4
Cybersecurity in Change Management — 1-5-4
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-6 · Periodical Cybersecurity Review and Audit 2
1-6-1
Periodical Cybersecurity Review and Audit — 1-6-1
Are OT/ICS cybersecurity controls reviewed and audited periodically for compliance?
Review/audit schedule; internal/external audit reports; corrective-action tracker.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-6-2
Periodical Cybersecurity Review and Audit — 1-6-2
Are OT/ICS cybersecurity controls reviewed and audited periodically for compliance?
Review/audit schedule; internal/external audit reports; corrective-action tracker.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-7 · Cybersecurity in Human Resources 2
1-7-1
Cybersecurity in Human Resources — 1-7-1
Are OT/ICS personnel cybersecurity risks managed before, during and after employment?
Screening for OT roles; security clauses in contracts; access revocation on exit.
NCA ECC-2NIS2Qatar NIAUAE IAADHICSISO 27001NCA CCCPCI DSS 4.0.1SAMA CSF
1-7-2
Cybersecurity in Human Resources — 1-7-2
Are OT/ICS personnel cybersecurity risks managed before, during and after employment?
Screening for OT roles; security clauses in contracts; access revocation on exit.
NCA ECC-2NIS2Qatar NIAUAE IAADHICSISO 27001NCA CCCPCI DSS 4.0.1SAMA CSF
1-8 · Cybersecurity Awareness and Training Program 2
1-8-1
Cybersecurity Awareness and Training Program — 1-8-1
Do OT/ICS staff and relevant third parties receive role-appropriate cybersecurity awareness and training?
OT awareness programme & schedule; attendance records; role-based training material.
CJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
1-8-2
Cybersecurity Awareness and Training Program — 1-8-2
Do OT/ICS staff and relevant third parties receive role-appropriate cybersecurity awareness and training?
OT awareness programme & schedule; attendance records; role-based training material.
2 sub-controls
- 1-8-2-1 1-8-2-1
- 1-8-2-2 1-8-2-2
CJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
2-1 · Asset Management 2
2-1-1
Asset Management — 2-1-1
Do you maintain an accurate, detailed OT/ICS asset inventory (incl. classification and ownership)?
OT/ICS asset inventory; classification scheme; assigned asset owners.
5 sub-controls
- 2-1-1-1 2-1-1-1
- 2-1-1-2 2-1-1-2
- 2-1-1-3 2-1-1-3
- 2-1-1-4 2-1-1-4
- 2-1-1-5 2-1-1-5
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-1-2
Asset Management — 2-1-2
Do you maintain an accurate, detailed OT/ICS asset inventory (incl. classification and ownership)?
OT/ICS asset inventory; classification scheme; assigned asset owners.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-2 · Identity and Access Management 2
2-2-1
Identity and Access Management — 2-2-1
Is OT/ICS identity & access management enforced — least privilege, MFA where feasible, segregation, no shared accounts?
Access control procedure; privileged-access register; access-review records; MFA config.
11 sub-controls
- 2-2-1-1 2-2-1-1
- 2-2-1-2 2-2-1-2
- 2-2-1-3 2-2-1-3
- 2-2-1-4 2-2-1-4
- 2-2-1-5 2-2-1-5
- 2-2-1-6 2-2-1-6
- 2-2-1-7 2-2-1-7
- 2-2-1-8 2-2-1-8
- 2-2-1-9 2-2-1-9
- 2-2-1-10 2-2-1-10
- 2-2-1-11 2-2-1-11
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
2-2-2
Identity and Access Management — 2-2-2
Is OT/ICS identity & access management enforced — least privilege, MFA where feasible, segregation, no shared accounts?
Access control procedure; privileged-access register; access-review records; MFA config.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
2-3 · System and Processing Facilities Protection 2
2-3-1
System and Processing Facilities Protection — 2-3-1
Are OT/ICS systems and processing facilities (workstations, servers, SIS) hardened and protected against cyber risk?
Hardening baselines; SIS protection measures; removable-media & malware controls; config records.
13 sub-controls
- 2-3-1-1 2-3-1-1
- 2-3-1-2 2-3-1-2
- 2-3-1-3 2-3-1-3
- 2-3-1-4 2-3-1-4
- 2-3-1-5 2-3-1-5
- 2-3-1-6 2-3-1-6
- 2-3-1-7 2-3-1-7
- 2-3-1-8 2-3-1-8
- 2-3-1-9 2-3-1-9
- 2-3-1-10 2-3-1-10
- 2-3-1-11 2-3-1-11
- 2-3-1-12 2-3-1-12
- 2-3-1-13 2-3-1-13
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IADORAGDPR (EU)HIPAA Security RuleNIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021SAMA CSFUK GDPR
2-3-2
System and Processing Facilities Protection — 2-3-2
Are OT/ICS systems and processing facilities (workstations, servers, SIS) hardened and protected against cyber risk?
Hardening baselines; SIS protection measures; removable-media & malware controls; config records.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IADORAGDPR (EU)HIPAA Security RuleNIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021SAMA CSFUK GDPR
2-4 · Network Security Management 2
2-4-1
Network Security Management — 2-4-1
Is the OT/ICS network secured — segmentation/zoning, secure interconnections, IDS/monitoring, and isolation from IT/internet?
Network architecture/zoning diagram (IEC 62443 zones & conduits); firewall/DMZ rules; segregation evidence.
16 sub-controls
- 2-4-1-1 2-4-1-1
- 2-4-1-2 2-4-1-2
- 2-4-1-3 2-4-1-3
- 2-4-1-4 2-4-1-4
- 2-4-1-5 2-4-1-5
- 2-4-1-6 2-4-1-6
- 2-4-1-7 2-4-1-7
- 2-4-1-8 2-4-1-8
- 2-4-1-9 2-4-1-9
- 2-4-1-10 2-4-1-10
- 2-4-1-11 2-4-1-11
- 2-4-1-12 2-4-1-12
- 2-4-1-13 2-4-1-13
- 2-4-1-14 2-4-1-14
- 2-4-1-15 2-4-1-15
- 2-4-1-16 2-4-1-16
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
2-4-2
Network Security Management — 2-4-2
Is the OT/ICS network secured — segmentation/zoning, secure interconnections, IDS/monitoring, and isolation from IT/internet?
Network architecture/zoning diagram (IEC 62443 zones & conduits); firewall/DMZ rules; segregation evidence.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
2-5 · Mobile Devices Security 2
2-5-1
Mobile Devices Security — 2-5-1
Are mobile/portable devices (laptops, handheld configuration & test devices) used in OT environments secured?
Mobile device policy; portable-device controls; data-handling rules for OT field devices.
5 sub-controls
- 2-5-1-1 2-5-1-1
- 2-5-1-2 2-5-1-2
- 2-5-1-3 2-5-1-3
- 2-5-1-4 2-5-1-4
- 2-5-1-5 2-5-1-5
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
2-5-2
Mobile Devices Security — 2-5-2
Are mobile/portable devices (laptops, handheld configuration & test devices) used in OT environments secured?
Mobile device policy; portable-device controls; data-handling rules for OT field devices.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
2-6 · Data and Information Protection 2
2-6-1
Data and Information Protection — 2-6-1
Is OT/ICS data and information protected for confidentiality, integrity and availability per policy and law?
Data classification & handling procedures; integrity controls; data protection evidence.
4 sub-controls
- 2-6-1-1 2-6-1-1
- 2-6-1-2 2-6-1-2
- 2-6-1-3 2-6-1-3
- 2-6-1-4 2-6-1-4
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCHIPAA Security RuleNIS2SAMA CSF
2-6-2
Data and Information Protection — 2-6-2
Is OT/ICS data and information protected for confidentiality, integrity and availability per policy and law?
Data classification & handling procedures; integrity controls; data protection evidence.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCHIPAA Security RuleNIS2SAMA CSF
2-7 · Cryptography 2
2-7-1
Cryptography — 2-7-1
Are cryptographic controls applied appropriately in the OT/ICS environment (where they don't impair safety/availability)?
Cryptography standard for OT; key management; encryption-in-transit/at-rest evidence.
UAE IACJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
2-7-2
Cryptography — 2-7-2
Are cryptographic controls applied appropriately in the OT/ICS environment (where they don't impair safety/availability)?
Cryptography standard for OT; key management; encryption-in-transit/at-rest evidence.
UAE IACJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
2-8 · Backup and Recovery Management 2
2-8-1
Backup and Recovery Management — 2-8-1
Are OT/ICS backups taken, protected and recovery-tested to restore operations after disruption?
Backup policy & schedule for OT configs/data; restore-test results; offline/immutable backup evidence.
4 sub-controls
- 2-8-1-1 2-8-1-1
- 2-8-1-2 2-8-1-2
- 2-8-1-3 2-8-1-3
- 2-8-1-4 2-8-1-4
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
2-8-2
Backup and Recovery Management — 2-8-2
Are OT/ICS backups taken, protected and recovery-tested to restore operations after disruption?
Backup policy & schedule for OT configs/data; restore-test results; offline/immutable backup evidence.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
2-9 · Vulnerabilities Management 2
2-9-1
Vulnerabilities Management — 2-9-1
Is OT/ICS vulnerability management performed (identification, assessment, risk-based remediation) without disrupting operations?
Vulnerability management procedure; OT-safe scan results/passive discovery; remediation tracker.
3 sub-controls
- 2-9-1-1 2-9-1-1
- 2-9-1-2 2-9-1-2
- 2-9-1-3 2-9-1-3
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-9-2
Vulnerabilities Management — 2-9-2
Is OT/ICS vulnerability management performed (identification, assessment, risk-based remediation) without disrupting operations?
Vulnerability management procedure; OT-safe scan results/passive discovery; remediation tracker.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-10 · Penetration Testing 2
2-10-1
Penetration Testing — 2-10-1
Is OT/ICS penetration testing conducted safely and periodically by qualified testers?
Pen-test scope & schedule; OT-safe testing rules of engagement; test reports & remediation.
4 sub-controls
- 2-10-1-1 2-10-1-1
- 2-10-1-2 2-10-1-2
- 2-10-1-3 2-10-1-3
- 2-10-1-4 2-10-1-4
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-10-2
Penetration Testing — 2-10-2
Is OT/ICS penetration testing conducted safely and periodically by qualified testers?
Pen-test scope & schedule; OT-safe testing rules of engagement; test reports & remediation.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-11 · Cybersecurity Event Logs and Monitoring Management 2
2-11-1
Cybersecurity Event Logs and Monitoring Management — 2-11-1
Are OT/ICS cybersecurity event logs collected, monitored and retained (with time sync and protection)?
Logging standard; centralised log/SIEM coverage for OT; retention & time-sync config; monitoring records.
10 sub-controls
- 2-11-1-1 2-11-1-1
- 2-11-1-2 2-11-1-2
- 2-11-1-3 2-11-1-3
- 2-11-1-4 2-11-1-4
- 2-11-1-5 2-11-1-5
- 2-11-1-6 2-11-1-6
- 2-11-1-7 2-11-1-7
- 2-11-1-8 2-11-1-8
- 2-11-1-9 2-11-1-9
- 2-11-1-10 2-11-1-10
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-11-2
Cybersecurity Event Logs and Monitoring Management — 2-11-2
Are OT/ICS cybersecurity event logs collected, monitored and retained (with time sync and protection)?
Logging standard; centralised log/SIEM coverage for OT; retention & time-sync config; monitoring records.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-12 · Cybersecurity Incident and Threat Management 2
2-12-1
Cybersecurity Incident and Threat Management — 2-12-1
Is OT/ICS cybersecurity incident and threat management in place (detection, response, reporting to NCA)?
Incident response plan covering OT; CSIRT/contacts; classification scheme; NCA reporting evidence; exercise reports.
8 sub-controls
- 2-12-1-1 2-12-1-1
- 2-12-1-2 2-12-1-2
- 2-12-1-3 2-12-1-3
- 2-12-1-4 2-12-1-4
- 2-12-1-5 2-12-1-5
- 2-12-1-6 2-12-1-6
- 2-12-1-7 2-12-1-7
- 2-12-1-8 2-12-1-8
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-12-2
Cybersecurity Incident and Threat Management — 2-12-2
Is OT/ICS cybersecurity incident and threat management in place (detection, response, reporting to NCA)?
Incident response plan covering OT; CSIRT/contacts; classification scheme; NCA reporting evidence; exercise reports.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-13 · Physical Security 2
2-13-1
Physical Security — 2-13-1
Is physical security of OT/ICS facilities and equipment enforced (access control, monitoring, environmental)?
Physical access controls & logs; CCTV/monitoring; environmental controls for OT areas.
9 sub-controls
- 2-13-1-1 2-13-1-1
- 2-13-1-2 2-13-1-2
- 2-13-1-3 2-13-1-3
- 2-13-1-4 2-13-1-4
- 2-13-1-5 2-13-1-5
- 2-13-1-6 2-13-1-6
- 2-13-1-7 2-13-1-7
- 2-13-1-8 2-13-1-8
- 2-13-1-9 2-13-1-9
ADHICSHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-13-2
Physical Security — 2-13-2
Is physical security of OT/ICS facilities and equipment enforced (access control, monitoring, environmental)?
Physical access controls & logs; CCTV/monitoring; environmental controls for OT areas.
ADHICSHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
3-1 · Business Continuity Management (BCM) 2
3-1-1
Business Continuity Management (BCM) — 3-1-1
Is OT/ICS business continuity managed — BIA, continuity/recovery plans, and tested resilience?
Business Impact Analysis; OT continuity & recovery plans (RTO/RPO); continuity test results.
6 sub-controls
- 3-1-1-1 3-1-1-1
- 3-1-1-2 3-1-1-2
- 3-1-1-3 3-1-1-3
- 3-1-1-4 3-1-1-4
- 3-1-1-5 3-1-1-5
- 3-1-1-6 3-1-1-6
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
3-1-2
Business Continuity Management (BCM) — 3-1-2
Is OT/ICS business continuity managed — BIA, continuity/recovery plans, and tested resilience?
Business Impact Analysis; OT continuity & recovery plans (RTO/RPO); continuity test results.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
4-1 · Third-Party Cybersecurity 2
4-1-1
Third-Party Cybersecurity — 4-1-1
Are third-party cybersecurity risks managed across OT/ICS hardware/software vendors and service providers?
Third-party security requirements & contracts; vendor risk assessments; monitoring & remote-access controls.
4 sub-controls
- 4-1-1-1 4-1-1-1
- 4-1-1-2 4-1-1-2
- 4-1-1-3 4-1-1-3
- 4-1-1-4 4-1-1-4
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
4-1-2
Third-Party Cybersecurity — 4-1-2
Are third-party cybersecurity risks managed across OT/ICS hardware/software vendors and service providers?
Third-party security requirements & contracts; vendor risk assessments; monitoring & remote-access controls.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR